Skip to main content
Mallory
MalwareRansomwareUsed by 3 actors

ADRecon

ADRecon is an open-source PowerShell-based Active Directory reconnaissance tool used to collect extensive information from AD environments. The provided content states it can gather data including ACLs, DNS zones, BitLocker recovery keys, LAPS passwords, domain accounts, and SPN credential hashes. It is executed as scripts such as ADRecon.ps1 and has also been observed renamed as dra.ps1 or recovered as obfuscated scripts such as C:\osit\r.ps1. Reported use cases in the content are post-compromise enterprise reconnaissance and privilege-escalation support, particularly to enumerate AD environments and help attackers progress toward Domain Admin access. The tool is associated in the content with multiple threat actors and intrusion sets, including VOID MANTICORE, BlackCat/ALPHV intrusions or affiliates, UNC3944, and Octo Tempest. It is described as being used alongside other reconnaissance or credential-access tooling such as PingCastle, ADFind, and Mimikatz. The content specifically notes its use in intrusions affecting Windows enterprise environments with Active Directory, including destructive and extortion-focused operations. No unique malware-style network indicators or hashes for ADRecon itself are provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
BlackCat

The file was identified as ‘ADRecon’, an open-source PowerShell tool specifically designed to gather extensive information about Active Directory (AD) environments, including ACLs, DNS zones, BitLocker recovery keys, LAPS passwords, Domain accounts, and SPN credential hashes.

via sygniasygnia.co
Handala

VOID MANTICORE has utilized ADRecon to enumerate the active directory environment.

via mitre attack websiteattack.mitre.org
Scattered Spider

...download tools such as Mimikatz, ADRecon...

via mandiant threat intelligencecloud.google.com
MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1059.001PowerShellEvidence1
TacticExecution

These included executing PowerShell commands... The threat actor created the ‘C:\Intel\45.ps1’ file... and executed it using PowerShell... Day 5: The threat actor used PowerShell to download and execute a script named ‘vic64.ps1’.

Stealth

1 technique
T1070.004File DeletionEvidence1
TacticStealth

the threat actor uploaded the ‘netscan.exe’ file to the same folder, used it to scan the domain, and deleted it after the scan activity was completed... the file no longer existed after execution – presumably it was deleted by the threat actor.

Discovery

5 techniques
T1018Remote System DiscoveryEvidence4
TacticDiscovery

the threat actor utilized ‘nslookup’ and ‘dir’ commands to carry out reconnaissance of a server in a different domain... scan the domain... enumeration of the Admins group in the new domain.

T1069.002Domain GroupsEvidence1
TacticDiscovery

Later, the threat actor utilized a user account to remotely deploy Cobalt Strike Beacon on a server in a third domain, followed by network scans and enumeration of the Admins group in the new domain.

T1083File and Directory DiscoveryEvidence1
TacticDiscovery

The threat actor leveraged the SoftPerfect tool to perform several manual reconnaissance activities, which included searching for passwords in Group Policy xml files, accessing remote folders via Windows Explorer...

T1087.002Domain AccountEvidence3
TacticDiscovery

T1087.002 - Domain Account Description from ATT&CK. Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior.

T1482Domain Trust DiscoveryEvidence1
TacticDiscovery

...running ADRecon (e.g., dra.ps1) to reach Domain Admin and enable broad destructive action.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.

ADRecon | Mallory